PT-2026-35009 · Linux+2 · Linux Kernel+2

CVE-2026-31657

·

Published

2026-04-06

·

Updated

2026-09-02

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description In the batman-adv module, the function batadv bla add claim() can replace claim->backbone gw and drop the last reference of the old gateway while readers are still following the pointer. The netlink claim dump path dereferences claim->backbone gw->orig and takes claim->backbone gw->crc lock without pinning the underlying backbone gateway. Additionally, the function batadv bla check claim() utilizes the same naked pointer access pattern.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-83810
BDU:2026-10733
CVE-2026-31657
ECHO-3B89-A04B-E497
LSN-0121-1
OPENSUSE-SU-2026:21555-1
SUSE-SU-2026:23066-1
SUSE-SU-2026:23068-1
SUSE-SU-2026:23193-1
SUSE-SU-2026:23194-1
SUSE-SU-2026:23221-1
SUSE-SU-2026:23231-1
SUSE-SU-2026:23237-1
SUSE-SU-2026:23241-1
SUSE-SU-2026:23244-1
SUSE-SU-2026:3130-1
SUSE-SU-2026:3166-1
USN-8490-1
USN-8490-2
USN-8491-1
USN-8492-1
USN-8492-2
USN-8492-3
USN-8492-4
USN-8492-5
USN-8493-1
USN-8493-2
USN-8497-1
USN-8498-1
USN-8499-1
USN-8508-1
USN-8527-1
USN-8528-1
USN-8545-1
USN-8546-1
USN-8547-1
USN-8547-2
USN-8604-1
USN-8605-1
USN-8606-1
USN-8607-1
USN-8609-1
USN-8619-1
USN-8633-1
USN-8633-2
USN-8635-1
USN-8645-1
USN-8666-1
USN-8666-2
USN-8666-3
USN-8667-1
USN-8715-1

Affected Products

Linuxmint
Linux Kernel
Ubuntu